CVE-2016-3801
published 2016-07-11CVE-2016-3801: The MediaTek GPS driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal…
PriorityP431high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.41%
33.9th percentile
The MediaTek GPS driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28174914 and MediaTek internal bug ALPS02688853.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 6.0.1 | — | |
| android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-76x6-94j9-g6p2: The MediaTek GPS driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android
ghsa_unreviewed·2022-05-17
CVE-2016-3801 [HIGH] GHSA-76x6-94j9-g6p2: The MediaTek GPS driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android
The MediaTek GPS driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28174914 and MediaTek internal bug ALPS02688853.
OSV
CVE-2016-3801: The MediaTek GPS driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android
osv·2016-07-11·CVSS 7.8
CVE-2016-3801 [HIGH] CVE-2016-3801: The MediaTek GPS driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android
The MediaTek GPS driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28174914 and MediaTek internal bug ALPS02688853.
Android
CVE-2016-3801: Android Security Bulletin 2016-07-01
CVE: CVE-2016-3801
Severity: HIGH
References: A-28174914*
M-ALPS02688853
vendor_android·2016-07-01·CVSS 7.8
CVE-2016-3801 [HIGH] CVE-2016-3801: Android Security Bulletin 2016-07-01
CVE: CVE-2016-3801
Severity: HIGH
References: A-28174914*
M-ALPS02688853
Android Security Bulletin 2016-07-01
CVE: CVE-2016-3801
Severity: HIGH
References: A-28174914*
M-ALPS02688853
No detection rules found.
No public exploits indexed.
arXiv
Mission Aware Cyber-physical Security
arxiv_fulltext·2025-10-23
Mission Aware Cyber-physical Security
Mission Aware Cyber-physical Security
[1]Georgios Bakirtzis
[2]Bryan Carter
[3]Cody H. Fleming
[4]Carl R. Elks
[1]LTCI, Télécom Paris, Institut Polytechnique de Paris
[2]University of Virginia
[3]Iowa State University
[4]Virginia Commonwealth University
Cody Fleming PhD, Iowa State University, Ames, Iowa, 50011, USA
[email protected]
## Abstract
Perimeter cybersecurity, while essential, has proven insufficient against sophisticated, coordinated, and cyber-physical attacks. In contrast, mission-centric cybersecurity emphasizes finding evidence of attack impact on mission success, allowing for targeted resource allocation to mitigate vulnerabilities and protect critical assets. Mission Aware is a systems-theoretic cybersecurity analysis that identifies components which, if compromised,
arXiv
A Model-Based Approach to Security Analysis for Cyber-Physical Systems
arxiv_fulltext·2018-06-10
A Model-Based Approach to Security Analysis for Cyber-Physical Systems
## Abstract
Evaluating the security of cyber-physical systems throughout their life cycle is necessary to assure that they can be deployed and operated in safety-critical applications, such as infrastructure, military, and transportation. Most safety and security decisions that can have major effects on mitigation strategy options after deployment are made early in the system's life cycle. To allow for a vulnerability analysis before deployment, a sufficient well-formed model has to be constructed. To construct such a model we produce a taxonomy of attributes; that is, a generalized schema for system attributes. This schema captures the necessary specificity that characterizes a possible real system and can also map to the attack vector space associated with the model's attributes. In thi
2016-07-11
Published